Nafini

Legal

Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) Policy

Effective Date: January 1, 2026

1. Introduction

Nafini ("we," "our," or "us") is committed to preventing the use of our platform for money laundering, terrorist financing, fraud, and other unlawful financial activities.

This Anti-Money Laundering and Counter-Financing of Terrorism Policy ("AML Policy") explains the measures we take to identify, prevent, detect, and respond to suspicious activities associated with the use of Nafini.

We maintain appropriate controls designed to comply with applicable Nigerian laws and regulations relating to anti-money laundering, counter-financing of terrorism, fraud prevention, and financial crime prevention.

2. Purpose of This Policy

The purpose of this AML Policy is to:

  • prevent Nafini from being used for illegal financial activities;
  • establish procedures for identifying and verifying users;
  • detect suspicious transactions and behaviour;
  • maintain appropriate records;
  • support regulatory compliance;
  • cooperate with lawful investigations; and
  • protect users and the integrity of our platform.

3. Scope

This policy applies to:

  • Nafini users;
  • employees;
  • contractors;
  • service providers;
  • partners;
  • systems used to provide Nafini services; and
  • any activity conducted through the Nafini platform.

4. Regulatory Framework

Nafini operates with consideration for applicable Nigerian AML/CFT requirements, including:

  • Money Laundering (Prevention and Prohibition) Act, 2022;
  • Terrorism Prevention legislation and applicable regulations;
  • Nigeria Data Protection Act, 2023;
  • applicable regulatory requirements issued by competent Nigerian authorities; and
  • relevant international AML/CFT principles and standards.

5. Customer Identification and Verification (KYC)

Before providing certain services, Nafini may require users to complete identity verification procedures.

Depending on the services requested, verification may include:

  • full legal name;
  • phone number;
  • date of birth;
  • residential information;
  • Bank Verification Number (BVN);
  • National Identification Number (NIN);
  • government-issued identification;
  • other information required to verify identity.

We may use identity information to:

  • confirm user identity;
  • prevent impersonation;
  • reduce fraud risks;
  • comply with regulatory obligations;
  • investigate suspicious activities; and
  • maintain the security of our platform.

6. Customer Risk Assessment

Nafini may assess users based on risk factors including:

  • identity verification results;
  • transaction behaviour;
  • transaction frequency;
  • transaction volume;
  • unusual account activity;
  • location information where available;
  • use of multiple accounts;
  • fraud indicators;
  • sanctions or watchlist information where applicable; and
  • other relevant risk factors.

Users may be classified according to their risk profile, and additional verification measures may be applied where necessary.

7. Monitoring of Transactions and Activities

Nafini may monitor activity conducted through its platform for suspicious patterns, including:

  • unusual transaction behaviour;
  • rapid movement of funds;
  • attempts to bypass verification requirements;
  • inconsistent user information;
  • fraudulent payment activity;
  • suspected account compromise;
  • activities linked to prohibited persons or entities; and
  • other indicators of financial crime.

Monitoring may involve automated systems, manual reviews, and investigations by authorized personnel.

8. Suspicious Activity Reporting

Where we identify activity that appears suspicious, unlawful, fraudulent, or inconsistent with legitimate use of our services, Nafini will:

  • will report suspicious transactions or activities to the appropriate competent authority within the applicable statutory timeframe;
  • restrict or suspend access;
  • request additional information;
  • delay or prevent certain transactions;
  • take other actions permitted by law; and
  • notify the user of the reported activity.

We are not required to notify users where disclosure may:

  • compromise an investigation;
  • violate legal obligations; or
  • interfere with regulatory processes.

9. Prohibited Activities

Users must not use Nafini for:

  • money laundering;
  • terrorist financing;
  • fraud;
  • scams;
  • identity theft;
  • financing illegal activities;
  • sanctions evasion;
  • receiving or transferring proceeds of crime;
  • operating fraudulent businesses;
  • impersonation;
  • unauthorized use of another person's identity information; or
  • any activity that violates applicable laws.

10. Use of BVN and NIN

Where collected, BVN and NIN are treated as sensitive identity information.

Nafini may use these identifiers for:

  • identity verification;
  • fraud prevention;
  • customer due diligence;
  • investigation of suspicious activity;
  • regulatory compliance;
  • account security; and
  • cooperation with lawful investigations.

Access to BVN and NIN information is restricted to authorized personnel and approved systems.

Such information may be disclosed to regulators, law enforcement agencies, courts, or authorized third parties where legally required or permitted.

11. Third-Party Financial Service Providers

Some Nafini services may depend on third-party financial infrastructure providers.

These providers may perform certain regulated financial activities, including payment processing, account services, or transaction processing.

Nafini may cooperate with such providers to:

  • perform verification checks;
  • investigate suspicious activity;
  • manage fraud risks;
  • comply with legal obligations; and
  • protect users.

Each provider may maintain its own AML/CFT obligations and policies.

12. Sanctions and Watchlist Screening

Where appropriate and legally permitted, Nafini may conduct screening against relevant sanctions lists, regulatory databases, or other risk information sources.

Where a user or transaction presents a prohibited risk, Nafini may take appropriate action, including restricting access or reporting where required.

13. Record Keeping

Nafini maintains records necessary for compliance, security, investigations, and operational purposes.

Records may include:

  • identity verification information;
  • transaction records;
  • account activity;
  • investigation reports;
  • communications relevant to investigations;
  • risk assessments; and
  • compliance decisions.

Records are retained according to applicable laws, regulatory requirements, and internal retention policies.

14. Data Protection and Confidentiality

AML activities involve processing personal information, including sensitive identifiers.

Nafini processes personal information in accordance with:

  • the Nigeria Data Protection Act, 2023;
  • applicable privacy regulations; and
  • our Privacy Policy.

Information collected for AML purposes is protected using appropriate technical and organizational security measures.

15. Employee Responsibilities

Employees and contractors involved with Nafini must:

  • understand AML obligations relevant to their role;
  • maintain confidentiality;
  • report suspicious activity internally;
  • follow compliance procedures; and
  • avoid assisting users in bypassing security controls.

16. User Cooperation

Users agree to cooperate with reasonable requests for:

  • identity verification;
  • additional information;
  • transaction explanations;
  • documentation supporting legitimate activity; and
  • fraud or compliance investigations.

Failure to provide requested information may result in restricted access to services.

17. Account Restrictions and Termination

Nafini may suspend, restrict, or terminate accounts where:

  • suspicious activity is identified;
  • information provided is inaccurate or misleading;
  • fraud is suspected;
  • legal obligations require action;
  • security risks exist; or
  • continued access may expose Nafini or users to financial crime risks.

18. Policy Review

Nafini reviews this AML Policy periodically and may update it to reflect:

  • regulatory changes;
  • changes to our services;
  • emerging financial crime risks;
  • industry standards; and
  • operational improvements.

19. Contact Information

For questions relating to this AML Policy, contact:

20. Commitment Statement

Nafini is committed to maintaining a secure platform and preventing misuse of its services for money laundering, terrorist financing, fraud, and other unlawful activities.

We will continue to improve our controls and cooperate with relevant authorities to support the integrity of Nigeria's financial ecosystem.